The short answer
Revisit — and, where needed, rerun — your DPIA whenever a change to a camera, its location or zone, the analytics model, or the processing purpose alters the nature, scope, context, or purpose of the processing. Treat it as a new activity especially if it adds biometrics, large-scale monitoring of a public area, or automated decisions. A like-for-like swap of the same camera in the same zone usually needs only documentation, not a full rerun.
Key takeaways
- A DPIA is not a one-off document; it must be kept under review and revisited whenever the nature, scope, context, or purpose of the processing changes materially.
- Changing a camera model, moving or re-aiming a camera into a new zone, and adding analytics are distinct events that can each change the risk picture independently.
- Adding people or facial recognition, behaviour analytics, or automated alerts to a system that only recorded before is a new processing activity, not a configuration tweak.
- A purpose change (for example reusing footage for staff performance or marketing) usually requires a fresh assessment and a new lawful basis, not just an amended form.
- If the revisits shows a residual high risk you cannot mitigate, you must consult the supervisory authority before starting or continuing the processing.
- Where the DPIA or its update is the only barrier between you and a prohibited use, the correct answer is to redesign the system, not to soften the assessment.
The trigger that forces a rethink
Regulators in the EU and the UK converge on the same test: a DPIA is required when processing is likely to result in a high risk to people's rights and freedoms, and the assessment must be kept under review and updated when the nature, scope, context, or purpose of the processing changes. Under the UK GDPR the ICO spells this out explicitly: you should carry out a new DPIA whenever there is a change to the nature, scope, context, or purposes of your processing.
For video surveillance, the practical consequence is that the original assessment has a limited shelf life. A system built for basic recording, assessed when installed, describes one risk picture. Every later decision to move a camera, upgrade its optics, add an analytics model, or reuse footage should be checked against that baseline description. If the change makes the stored or live image more identifying, covers more people or a more sensitive area, or feeds decisions about individuals, the original assumptions no longer hold.
- Does the change affect what personal data is captured, of whom, where, or for how long?
- Does the change introduce a new data category such as biometric data, or a new recipient such as the police or a cloud analytics provider?
- Does the change make an automated output more consequential for individuals, for example by locking a door or summoning security without a human step?
Changing the camera and the zone
Replacing a camera is routine, but a like-for-like swap and a meaningful upgrade are different events. If the new unit has the same position, resolution, field of view, retention, and analytics profile, the original DPIA largely still describes the reality; the proportionate response is to log the change in the DPIA and the record of processing rather than start from zero.
The moment the change alters what is visible, the risk moves. A camera moved so its field of view now covers a public street, a neighbouring property, a school entrance, or a space where people expect privacy — changing rooms, toilets, staff rest areas — changes the scope and context of the processing. In France, the CNIL notes that where a device results in the systematic monitoring on a large scale of a zone accessible to the public, a DPIA must be carried out; the same logic appears in the large-scale public-area monitoring trigger in the GDPR and UK GDPR.
- Higher resolution or a telephoto lens may make passers-by identifiable from what was previously anonymous; assess before keeping the footage.
- A camera aimed across a boundary or into a higher-privacy area typically fails the proportionality test unless the purpose and a less intrusive alternative are documented.
- Zone changes that add staff areas or homes to the picture usually escalate the risk from moderate to high and demand a fresh assessment.
Changing the model and adding analytics
The clearest escalation is moving from recording to analysis. A system that merely records and a camera that runs behaviour detection, object tracking, or identification are not treated alike: the European guidelines and the AI Act treat analytics that goes beyond simple counting as a different, higher-risk class of processing, and in several national settings algorithmic analysis of footage has been found to need an explicit legal basis of its own.
In 2026 the French Council of State upheld a CNIL decision preventing the City of Nice from deploying a school-entrance 'intrusion zone' system that algorithmically analysed footage and alerted municipal police. The Court held that automated algorithmic analysis is a distinct form of processing that requires a specific legislative basis, regardless of whether it is classified as high risk under the EU AI Act. The lesson for private operators is that layering any model that classifies, tracks, or alerts over raw video is a step-change in risk that the DPIA must describe before deployment.
- People counting that yields only aggregate numbers is low risk; any step that lets a person or a specific track be singled out raises the risk materially.
- Adding person or facial recognition, or processing embeddings that can be reversed into identifying features, triggers the biometric-data criteria and almost always requires a full DPIA before use.
- If the model's output sends an alert that leads to a decision about an individual, define and document a human-review step so the automated output is not the final decision.
Changing the analytics purpose
Purpose limitation is one of the strictest GDPR principles, and it bites hardest when footage is repurposed. Reusing video collected for loss prevention to assess staff performance, build marketing profiles, or count customers by demographic starts a new processing activity. The controller normally needs a distinct lawful basis, an updated privacy notice, and a re-run of the DPIA, because the data subjects, the likely harm, and the justification all change.
This is not merely an administrative re-labelling. The original balancing test that justified watching a loading bay for security does not automatically justify profiling the same people later. Document why the new purpose is compatible or, if it is not, obtain fresh consent or rely on a separate legal basis, and set the storage limitation against the new purpose before the data is reused.
- State the new purpose in writing and test it against purpose limitation and data minimisation before touching the footage.
- Check whether the new purpose changes the categories of data subjects — for example turning anonymous visitors into identified customers.
- Update the privacy notice and signage so people filmed can foresee the analytics, otherwise transparency fails.
Running the revisit: amend, rerun, or consult
A revisit can end in one of three ways: a documentation note, an amended DPIA, or a full re-run followed, in the worst case, by consultation with the supervisory authority under Article 36. Regulators advise starting early in the project and treating the DPIA as an iterative process that is corrected regularly, particularly on major changes in how the processing is carried out.
Decide the depth by looking at the criteria the European guidelines use to screen high risk: evaluation or scoring, automated decisions, systematic monitoring, sensitive or highly personal data, large-scale processing, combining datasets, vulnerable people, innovative technology, and preventing people from exercising a right. If a change stacks two or more of these, treat it as a full DPIA. If you identify a residual high risk that measures cannot bring down to an acceptable level, the law requires you to consult the authority before you begin.
- Schedule the DPIA review in the record of processing and in vendor change-management workflows, not just in the legal department.
- Version every DPIA so an auditor can see what changed and when, and keep the DPO's advice and any disagreement on file.
- When residual high risk cannot be mitigated, do not start processing; ask the authority for guidance first.
Limitations and jurisdiction
This guidance is general information about privacy governance, not legal advice for your specific deployment, and the requirements differ by jurisdiction. The examples are drawn mainly from EU GDPR practice, the UK GDPR as applied by the ICO, and the CNIL's French guidance; other regimes may set stricter or looser thresholds.
A DPIA also does not cure an otherwise unlawful use. The 2026 French ruling on algorithmic surveillance shows that even a complete impact assessment cannot authorise processing that lacks a legal basis. If the change in camera, model, zone, or purpose puts the operation outside what the law allows, the correct response is to redesign the system, not to expand the DPIA to cover it.
Put it into practice
DPIA Revisit Trigger Matrix for cameras, models, zones and purposes
Apply this matrix whenever any change to a camera, zone, model, or analytics purpose is proposed. For each row, confirm the facts, answer the question, and act on the default outcome. If two or more high-risk criteria stack up, treat the change as a full DPIA and consult the authority on any residual high risk.
- Camera replaced with the same model, in the same position and zone, same purpose and retention: log the swap in the DPIA and the record of processing; no full rerun.
- Camera resolution or field of view increased: does it capture more identifiable detail or more people than before? If yes, assess and amend the DPIA before relying on the sharper images.
- Camera added or re-aimed in a zone of high privacy expectation (changing room, toilet, staff rest area, overlooking a home): full DPIA before use; such placement may be unjustifiable.
- Camera moved to a publicly accessible place monitored on a large scale: full DPIA, matching the systematic large-scale public-area trigger in the GDPR and UK GDPR.
- Analytics switched from aggregate people counting to object or behaviour tracking: new risk; amend the DPIA or rerun it, depending on whether individuals become identifiable.
- Person or facial recognition, or biometric embeddings, added to any camera: full DPIA before deployment, and treat biometric processing on a large scale as a reason to consult the authority on residual risk.
- Model output now sends automated alerts to staff, security, or the police: document a human-review step for any decision affecting an individual and update the DPIA for automated-decision risk.
- Footage repurposed for a new end, such as staff performance or marketing: full assessment, likely a new lawful basis, and an updated privacy notice before reuse.
- Retention period extended or footage shared with a third party: assess and amend the DPIA before implementing, and update the processor or sharing records.
- Analytics vendor or model version changed while purpose, zones, and retention stay the same: verify the new model does not add identification or tracking capability; amend the DPIA and update processor records.
Questions people ask
Do I need a completely new DPIA every time I replace a camera?
No. If you swap a camera for the same model in the same position and zone, with the same resolution, retention, and analytics profile, the original assessment still describes the processing accurately. The proportionate response is to log the replacement in the DPIA and the record of processing. A new or materially revised DPIA is needed when the replacement changes what is captured — higher resolution, a wider field of view, a new zone, or added analytics.
Is adding facial recognition just a configuration change?
No. Moving from recording, or from aggregate counting, to identification is a new processing activity. It introduces biometric data, which is a special category under Article 9, and typically triggers several high-risk criteria at once. You should carry out a full DPIA before deployment, confirm a lawful basis and special-category condition, and if a residual high risk cannot be mitigated, consult the supervisory authority before you begin.
What counts as a material change that forces me to revisit the DPIA?
Regulators point to changes in the nature, scope, context, or purpose of the processing. In practice that means a new category of personal data (such as biometrics), more data subjects or a more sensitive area, a new recipient or international transfer, longer retention, automated decisions about individuals, or a new purpose such as staff monitoring or marketing. If the change stacks two or more high-risk criteria from the European guidelines, treat it as a full DPIA.
What if I only move one camera to a different zone and nothing else changes?
Moving a camera is significant whenever the new field of view changes what or whom it sees. If it now covers a public place on a large scale, a school entrance, a neighbouring property, or an area of high privacy expectation, the scope and context of the processing change and you should reassess. If it is re-aimed within the same low-risk zone and the purpose is unchanged, an amended note in the DPIA is usually sufficient.
When must I consult a supervisory authority about a change?
Under Article 36 of the GDPR you must consult the supervisory authority before processing if the DPIA identifies a high risk that you cannot mitigate by appropriate measures. The authority typically responds within eight weeks (extendable to 14 in complex cases under the UK GDPR). You cannot lawfully start the new processing while that residual high risk remains unresolved.
What records prove that I actually revisited the DPIA?
Version the DPIA and keep a dated change log showing what triggered each revision, the questions you asked, and the DPO's advice, including any disagreement. Link each version to the relevant entries in your record of processing, the privacy notice update, and the vendor or model change request. This chain of evidence is what a supervisory authority examines during an audit.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Data protection impact assessments — ICO guide to accountability and governanceInformation Commissioner's Office (ICO)
- Data Protection Impact Assessments (DPIAs) — ICO detailed guidanceInformation Commissioner's Office (ICO)
- Gérer les risques — l'analyse d'impact relative à la protection des données (AIPD)CNIL — LINC
- J'installe des caméras dans mon commerce, quelles sont les règles ?CNIL
- France Tightens the Legal Framework for Algorithmic Video Surveillance: The Council of State Upholds CNIL's Decision Against the City of NiceDe Gaulle Fleurance & Associés (DDG)
- GDPR and AI in Surveillance: Compliance in a New EraTechnolynx